- Products
- Learn
- Local User Groups
- Partners
- More
On-Premise SD-WAN Management
Register HereWhat's New in R82.10?
Watch Here AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
The Moment Before
Hi mates,
As our executives have requested it, I would like to gather some experience reports regarding the reliability of CP Geo IP data when using updatable objects.
Has anyone experienced complaints about incorrect country assignments for IP addresses? Or have the assignments generally been accurate?
Any experiences or feedback would be greatly appreciated.
thanks
Vince
I have couple customers. False positive can happen, if it happens you need to open TAC case. But I don't recall the last time I did that. The IP information comes from a third party. If you need to whitelist you have to do it yourself by making a bypass for the problematic IP. If you want it to be flagged correctly SR is needed. So yes it works, is it 100%, no but all extra tools can help in a better security
Make sure you do not use legacy geo protection.
Hey Vince,
I totally agree with @Lesley here. I also have not had many resports about false positives in the past (maybe 3 or 4), but opening TAC case usually takes care of it quickly.
maxmind.com is very reliable as far as those things.
Nobody has complained while my company has used updatable objects, so the geolocation is good enough for us. Currently dealing with a Cloudflare address showing up as Russian some of the time and USAian some of the time. Even two different views of exactly the same log entry seem to disagree on where it is. We only noticed it when proactively poking through geolocation drops recently.
I recommend building rules based on geolocations in a separate ordered layer. This makes it easier and safer to add exceptions should they be needed, since your normal firewall rules will still be applied to them.
We have not had any reports with outbound Geo Blocking being incorrect.
Inbound has been reliable in the terms of people going on vacation, reporting they cannot get logged in and the Geo Blocking accurately has picked up their vacation spot, which is blocked on purpose.
We have been using the updatable objects for a little over 3 years, no complaints.
I have couple customers. False positive can happen, if it happens you need to open TAC case. But I don't recall the last time I did that. The IP information comes from a third party. If you need to whitelist you have to do it yourself by making a bypass for the problematic IP. If you want it to be flagged correctly SR is needed. So yes it works, is it 100%, no but all extra tools can help in a better security
Make sure you do not use legacy geo protection.
Hey Vince,
I totally agree with @Lesley here. I also have not had many resports about false positives in the past (maybe 3 or 4), but opening TAC case usually takes care of it quickly.
maxmind.com is very reliable as far as those things.
Nobody has complained while my company has used updatable objects, so the geolocation is good enough for us. Currently dealing with a Cloudflare address showing up as Russian some of the time and USAian some of the time. Even two different views of exactly the same log entry seem to disagree on where it is. We only noticed it when proactively poking through geolocation drops recently.
I recommend building rules based on geolocations in a separate ordered layer. This makes it easier and safer to add exceptions should they be needed, since your normal firewall rules will still be applied to them.
We have not had any reports with outbound Geo Blocking being incorrect.
Inbound has been reliable in the terms of people going on vacation, reporting they cannot get logged in and the Geo Blocking accurately has picked up their vacation spot, which is blocked on purpose.
We have been using the updatable objects for a little over 3 years, no complaints.
Thanks all for your feedback. No complaints sounds good. We will talk bit more about that and decide.
Again, thanks all, much appreciated.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 9 | |
| 5 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Tue 28 Jul 2026 @ 11:00 AM (EDT)
Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based ThreatsThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayTue 28 Jul 2026 @ 11:00 AM (EDT)
Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based ThreatsThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY